feat(backend): Discord OAuth login with DB-backed sessions (#23) #31
Reference in New Issue
Block a user
Delete Branch "feat/discord-login"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Implements #23 per ADR-0002.
go test ./... passes.
Two-axis review (Standards + Spec) done. Spec: PASS on all 12 acceptance criteria + no-markup/no-secret addendum, evidence per criterion in review. Standards: near-clean pass; the one medium finding (oauthStates FIFO could grow without bound via start/cancel cycles) plus 8 low/nit findings all fixed in
1a7e130— FIFO replaced with oldest-expiry eviction, CreateSession now transactional, slices.Contains, APIBase rename, stale comments/paths, --ember-ink. go test ./... green.Review round 1 — security review of the initial implementation (verdict: APPROVE-WITH-NITS). Findings and what was done, all folded into the initial commit
13e8e73:go test ./... green.
Review round 2 — two-axis review (Standards + Spec) of
13e8e73.Spec axis: PASS on all 12 acceptance criteria plus the no-markup/no-secret addendum, each backed by test evidence: the stub-driven full-flow test asserts the form-encoded token exchange field-by-field, the single-guild membership endpoint path, refusal parity (non-member / missing role / member-403 all identical), the reader-count side-effect check, session expiry, logout revoke, zero remaining signing code, callback rate limiting, and that no Discord-supplied string is ever rendered.
Standards axis: near-clean; 1 medium + 8 low/nit findings, all fixed in
1a7e130(force-pushed over13e8e73):go test ./... green after all fixes.